Executive brief
The Linux kernel's BPF (Berkeley Packet Filter) subsystem contains a flaw in how it handles hash table batch operations. When a lock acquisition fails during batch lookups and deletes, the kernel silently skips the locked bucket, which can cause out-of-bounds memory access or inadvertently expose sensitive kernel memory to unprivileged user applications. This could allow a local attacker to read sensitive information from kernel memory.
Technical details
The vulnerability exists in the __htab_map_lookup_and_delete_batch() function in kernel/bpf/hashtab.c. When htab_lock_bucket() fails with -EBUSY, the code incorrectly advances to the next bucket instead of propagating the error back to userspace. If bucket_cnt is greater than bucket_size or zero, this can cause out-of-bounds memory access or leak kernel memory contents to userspace. The fix modifies error handling to call rcu_read_unlock() and bpf_enable_instrumentation() before returning -EBUSY to the caller, allowing user-space applications to retry or skip the busy batch. The vulnerability affects BPF hash table map batch operations and requires local access to invoke BPF syscalls. Patches are available in the Linux kernel stable tree across multiple versions.
Affected products
- Linux Linux kernel Multiple versions before fixes applied
Timeline
- 2022-08-31: disclosed
- 2022-10-21: patched